v0.48.13 · crafted in every detail

The agent for
perfectionists.

Crafted in every detail — it behaves in your team's chat and gets sharper the longer it runs. Sandboxed and self-managing.

bun add -g typeclaw

Talks to — and a websocket TUI

everything it does

Features crafted for perfectionists.

From a self-improving memory loop to a sandbox per agent, here is the whole surface — one capability per card.

Self-improving

It distills each day of work into long-term memory and reusable skills you can read in git.

Group chat

It reads the room, tells humans from bots, and stays quiet when a message was not meant for it.

Scheduling

Recurring prompts or shell commands and future reminders, fired at a timezone-safe instant.

Security

Layered guards, role gates, per-channel match rules, and encryption at rest for sensitive credentials.

Isolation & Sandbox

Each agent lives in its own folder and container, so nothing installs globally and agents never collide.

Subagents

It hands off research, planning, review, and execution to focused child sessions, sync or in the background.

Extensibility

Plugins are plain TypeScript imports; add MCP servers, lazy skills, and hot-reloadable typed config.

Compose

Discover agent folders and start, stop, check, and diagnose them across your fleet from the command line.

Memory you can read

It gets sharper while you sleep — building muscle memory you can read.

A dreaming subagent distills each day's work into long-term memory, and the moves it makes often become muscle memory — reusable skills it writes for itself and loads on later runs. It all lands as plain files, committed to git, so you can review what it picked up, revert what it got wrong, and own its memory like the rest of your code. Plain files you can read, not a black box.

Short-term

Streams

memory/streams/

Every reply and tool call lands in a daily log as it happens — the raw record of what it just did.

Long-term

Topics

memory/topics/

The dreaming subagent distills those days into sharded knowledge, one subject per file, that it can recall later.

Muscle memory

Skills

memory/skills/

Recurring procedures get written into reusable skills it loads automatically — things it can do without thinking them through again.

what it learns loops back into the next session

Knows when not to talk

It reads the room — and stays quiet when the message wasn't for it.

In a busy channel it tells humans from bots, tracks who's present, and engages on a structural decision rather than a guess. When a message clearly targets someone else, it holds back; mid-thread with you, it stays engaged without being re-mentioned, then steps back when the conversation moves on. Peer-bot loop guards and flood filters keep it from spiraling.

alex

@jordan can you take the deploy?

observing — not addressed to me

ci-botbot

build passed

sam

typeey, draft the changelog

typeey

On it — drafting the changelog now.

A bench of specialists

It delegates to focused specialists, each in a clean context.

It hands off research, planning, review, and hands-on execution to child sessions — each with its own system prompt, tools, and model. Spawn and wait for a result, or fan work out in the background and collect completions later. Coalescing drops duplicate concurrent runs and depth limits keep delegation chains bounded.

main session
researchown context
reviewown context
executeown context

Defense in depth

Every tool call runs a gauntlet before it fires.

Risky actions pass through layered guards classified by severity — secret exfiltration, SSRF, prompt injection, rogue git pushes, and silent privilege escalation get stopped before they happen. Roles gate who can bypass what, and each bash call runs inside its own sandbox. Powerful in trusted hands, contained everywhere else.

tool call
Guardsseverity-classified policies
Roleswho can bypass what
Sandboxeach bash call isolated
fires, contained

Operational autonomy

It knows its own config — so it won't strand itself.

It can back itself up, rebuild, and restart its own container through the host daemon. The difference: it knows which settings take effect live and which need a restart, so it won't brick itself with a change that silently does nothing. When it does restart, it hands off to the rebooted container and picks the same conversation back up — no cold-starting into silence. And when it keeps working on its own, hard budgets on turns, tokens, and wall-clock keep it from spiraling.

typeclaw.json
liverestart
"models": { … }live
"channels": { … }live
"alias": { … }live
"sandbox": "proc-bind"restart
"port": 8973restart

Plugin system

It writes its own tools — as TypeScript plugins.

When a recurring job needs more than it ships with — a custom tool, a scheduled hook, a new channel — it writes itself a plugin to do it. A plugin is just a TypeScript file that imports the runtime: no DSL, no IPC, no sidecar. The same language it already runs in, so the harness it builds for itself is code you can read and keep.

needs

post PR reviews to GitHub

no tool yet
written by my-agentplugins/pr-review.ts
import { definePlugin } from 'typeclaw/plugin'

export default definePlugin({
  plugin: () => ({
    tools: {
      postReview: {
        description: 'Post a PR review to GitHub',
        async execute({ url, body }) {
          /* … */
        },
      },
    },
  }),
})

postReview

now in its toolset

ready

one command to hatch

One init — wired, hatched, already learning.

my-agent

Use cases

For every workflow

Your newsletter digest, in your inbox by 8am.

  1. A cron job fires a web-research subagent overnight.

  2. It reads and summarizes the newsletters that landed.

  3. It posts the digest straight to your Telegram DM.

Memory remembers which sources you skip, so the next digest skips them too.

Telegram DM
typeey08:00

Good morning. Here's what landed overnight:

— AI Weekly: new model benchmarks

— Frontend Digest: View Transitions ship

Live right now

This page's mascot reviews real pull requests on TypeClaw's own repo — unprompted, line by line.

Request @typeey as a reviewer and it reads the diff, thinks it through, and posts a formal review back. No human pressing a button. The whole setup is one recipe you can copy.

how it compares

Where TypeClaw is the right choice.

These are all good — genuinely. Reach for OpenClaw when you want the biggest ecosystem, Hermes when Python is your stack. Reach for TypeClaw when you want a runtime you can read end to end, extend with an import, and keep as your own.

Feature
OpenClaw
TypeScript

Biggest ecosystem

a platform to learn, not a codebase to read

Hermes Agent
Python

Mature, self-improving

Python — a boundary if your stack is TS

TypeClawyou are here
TypeScript

One TS codebase, plugins as imports

younger, smaller ecosystem

Knows when not to talkYesPartialYes
Per-agent isolationYesPartialYes
Plugins as importsYesNoYes
Permissions & guardsYesYesYes
Per-agent git repoPartialYesYes
Self-managingPartialYesYes

These are all capable runtimes. OpenClaw is the broad platform; Hermes is the mature Python agent. TypeClaw's edge is the combination: one readable TypeScript codebase you own — memory you can diff in its own git repo, isolated per agent, and extended with a plain import.

built for people like you

Made with care. Now make it yours.

Every detail here was sweated over — because the details are the point. One folder, one container, one language you already know. Spin one up, read it end to end, and shape it until it's exactly the agent you wanted. Trying it costs nothing.